Pith. sign in

REVIEW 2 cited by

Adversarial Risk Bounds via Function Transformation

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 1810.09519 v2 pith:D7CXCN73 submitted 2018-10-22 stat.ML cs.LG

classification stat.MLcs.LG
keywords riskadversarialboundsfunctionclassesderivederivingdiscuss
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

We derive bounds for a notion of adversarial risk, designed to characterize the robustness of linear and neural network classifiers to adversarial perturbations. Specifically, we introduce a new class of function transformations with the property that the risk of the transformed functions upper-bounds the adversarial risk of the original functions. This reduces the problem of deriving bounds on the adversarial risk to the problem of deriving risk bounds using standard learning-theoretic techniques. We then derive bounds on the Rademacher complexities of the transformed function classes, obtaining error rates on the same order as the generalization error of the original function classes. We also discuss extensions of our theory to multiclass classification and regression. Finally, we provide two algorithms for optimizing the adversarial risk bounds in the linear case, and discuss connections to regularization and distributional robustness.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 2 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Adversarial learning for nonparametric regression: Minimax rate and adaptive estimation

    stat.ML 2025-06 conditional novelty 8.0 of 10

    For smooth nonparametric regression under future X-attacks, the minimax adversarial Lq risk is the standard no-attack rate plus r^{q(1∧β)}, and a piecewise local polynomial estimator attains it.

  2. Adversarial Training from Mean Field Perspective

    cs.LG 2025-05 reject novelty 7.0 of 10

    A mean field framework for random ReLU networks yields adversarial-loss bounds and predicts that adversarial training shrinks weights, hurts vanilla depth, and is rescued by residual connections and width.

Pith tools